Skip to content
NetarxImpact Database
Smishing (SMS)No AI reportedConfirmed

Twilio breached by 0ktapus SMS phishing kit that hit 163 downstream customers

Twilio · Technology · United States · August 4, 2022

What happened

In August 2022 Twilio disclosed that attackers had phished employee credentials by SMS and used them to access internal applications and a number of customer accounts. Okta's analysis of the actor, which it tracks as Scatter Swine, confirmed that 163 Twilio customers were affected, including Okta itself, and Twilio later said Authy two-factor app users were also touched. The same kit was used against more than a hundred organisations.

How the deception worked

The actor sent bulk SMS lures to employees and in some cases their family members, warning of expired passwords or schedule changes and linking to domains built from templates such as company-okta.com or company-vpn.net. The pages cloned the target's real single sign-on portal and relayed submitted usernames and passwords to the operators over Telegram within seconds. Because the stolen credentials arrived live, operators could immediately trigger an SMS one-time-passcode challenge and, in Twilio's case, use console access to read the passcodes sent during those challenges, defeating SMS-based MFA and reaching internal systems and customer data.

AI involvement · No AI reported

No AI element reported; the kit relayed credentials to operators via Telegram in real time.

The control that would have caught it· our reading, not a claim from the sources

SMS one-time passcodes are relayable in real time; only origin-bound authenticators such as FIDO2 keys stop this kit, and lookalike-domain monitoring shortens the detection window.

Sources (4)

  1. Detecting Scatter Swine: Insights into a Relentless Phishing Campaign
    Okta Security·sec.okta.comOpen ↗
  2. Twilio confirms data breach after its employees got phished
    Help Net Security·helpnetsecurity.comOpen ↗
  3. Twilio says breach also compromised Authy two-factor app users
    TechCrunch·techcrunch.comOpen ↗
  4. Incident Report: Employee and Customer Account Compromise
    Twilio·twilio.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.